Microsoft Internet Explorer 8 Javascript RegExpBase::FBadHeader Use-After-Free

A specially crafted web-page can cause the Javascript engine of Microsoft Internet Explorer 8 to free memory used for a string. The code will keep a reference to the string and can be forced to reuse it when compiling a regular expression.

Leave a Reply